SAQ D
PCIComplianceHubLast updated
The catch-all Self-Assessment Questionnaire, published in two versions. SAQ D for Merchants applies to any merchant eligible to self-assess that does not meet the criteria for a more specific questionnaire, including any merchant that stores account data electronically. SAQ D for Service Providers applies to service providers eligible to self-assess. Both cover essentially every PCI DSS requirement, making SAQ D far larger than the others and close in scope to a Report on Compliance.
Applies to. SAQ D for Merchants: any merchant eligible to self-assess that fits no other SAQ, including any merchant that stores account data electronically. SAQ D for Service Providers: the only SAQ a service provider may use.
Limits. SAQ D covers the requirements the other questionnaires omit, so it is close to a ROC in scope and effort. Fitting a narrower SAQ's description is not enough; the entity has to meet every criterion of that SAQ, and if it fails one it is on SAQ D.